Skip to content

chore: bump pinned CodeQL CLI to v2.27.2 and release v0.8.2 - #236

Open
security-lab-bot[bot] wants to merge 2 commits into
mainfrom
chore/update-codeql-cli-2.27.2
Open

security-lab-bot[bot] wants to merge 2 commits into
mainfrom
chore/update-codeql-cli-2.27.2

Conversation

@security-lab-bot

Copy link
Copy Markdown
Contributor

Automated CLI version bump, requested via the "Update CodeQL CLI Version"
workflow (workflow_dispatch, codeql_version: 2.27.2, release_bump: patch).

This PR:

  • Updates .codeqlversion to 2.27.2.

  • Pins every codeql/<lang>-all / codeql/<lang>-queries dependencies:
    entry across query/library qlpack.yml files (not */ext or
    */ext-library-sources, whose extensionTargets is intentionally left
    unconstrained and must never be auto-rewritten) to the exact version
    shipped in the official CodeQL Bundle for this CLI release (see
    .github/scripts/pin-codeql-library-versions.sh) - this keeps
    codeql pack upgrade from jumping those libraries to registry-latest instead
    of the version this CLI actually ships/tests against.

  • Runs codeql pack upgrade <dir> for every query/library pack directory (again
    excluding */ext and */ext-library-sources) to refresh its
    codeql-pack.lock.yml against the new CLI and pinned library versions.

  • Also bumps the repo release version (patch, via the same
    patch-release-me step update-release.yml uses) to 0.8.2,
    propagating it to every pack's own version: field, configs/*.yml
    references, and cross-pack -libs pins.

Merging this PR triggers the real batch publish - publish.yml's
auto-trigger fires on any push to main that changes .release.yml, which this
PR does. No separate "CodeQL Update Release" run is needed. That run's summary
job will create the matching GitHub Release as a full release
(release_prerelease: false).

Remaining steps (see CONTRIBUTING.md's "Updating the pinned CodeQL CLI/library
version" section):

  • Check CI on this PR - fix any compilation/test errors caused by upstream
    API changes. This is usually the hardest part; consider delegating it to a
    Copilot coding agent session pointed at this PR/branch.
  • Review and merge - this alone will trigger the real batch publish.

@felickz

felickz commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

@copilot 2.27.2 has some breaking changes - is this why our ci is failing? https://github.com/GitHubSecurityLab/CodeQL-Community-Packs/actions/runs/37988104873/job/114028147745?pr=236

Please fix

Breaking Changes
Golang
The Go control flow graph (CFG) implementation has been completely rewritten to use the shared CFG library. The CFG now includes additional nodes to more accurately represent certain constructs, including assignments, function parameters and results, range statements, and deferred calls. The CFG now only includes nodes that are reachable from the entry point. Basic blocks are also now constructed directly from the shared CFG. Existing code that relies on specific CFG nodes, edges, locations, textual representations, or basic block boundaries may need to be updated. Additionally, the following API changes have been made:

BasicBlocks::Cfg has been removed. BasicBlock now directly uses the basic-block implementation provided by the shared CFG library.

ControlFlow::EntryNode and ControlFlow::ExitNode have been added, and ControlFlow::entryNode and ControlFlow::exitNode now return these more specific types.

IfStmt.getCond has been deprecated. Please use the new IfStmt.getCondition instead.

The result types of IfStmt.getThen and LoopStmt.getBody have been widened from BlockStmt to Stmt.

SwitchStmt.getExpr has been added, providing a common accessor for the expression examined by expression and type switches.

Several IR instruction classes have been removed or consolidated, including ReadArgumentInstruction, InitResultInstruction, IncDecInstruction, EvalIncDecRhsInstruction, EvalImplicitOneInstruction, SelectInstruction, and SendInstruction.

EvalCompoundAssignRhsInstruction now also represents increment and decrement operations, and it and EvalImplicitInitInstruction directly represent their associated writes.

Co-authored-by: felickz <1760475+felickz@users.noreply.github.com>

Copilot AI commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

@copilot 2.27.2 has some breaking changes - is this why our ci is failing? https://github.com/GitHubSecurityLab/CodeQL-Community-Packs/actions/runs/37988104873/job/114028147745?pr=236

Please fix
...

Yes, the CodeQL 2.27.2 Go CFG rewrite changed internal provenance IDs, not the detected source-to-sink path. I updated the test expectation; all 3 Go tests pass. Commit: cbcca1f.

Copilot AI requested a review from felickz October 10, 2026 02:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants